TOTOLINK A3002R Stack-Based Buffer Overflow Vulnerability

Vulnerability

A critical stack-based buffer overflow vulnerability has been identified in the TOTOLINK A3002R router, specifically in the firmware version 1.1.1-B20200824.0128. The issue arises in the 'formRoute' function of the file '/boafrm/formRoute', where the 'subnet' argument can be manipulated, allowing remote attackers to overflow the stack. This vulnerability could potentially be exploited to execute arbitrary code.

Impact

Exploitation of this vulnerability leads to a stack-based buffer overflow, allowing for arbitrary code execution.

Added: Jun 22, 2025, 6:21 PM
Updated: Jun 22, 2025, 6:21 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
6.2
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.